-

CVE-2026-80904

Medienbericht

net/tls: Fail tls_sw_splice_read() after a failed async decrypt

In the Linux kernel, the following vulnerability has been resolved:

net/tls: Fail tls_sw_splice_read() after a failed async decrypt

When an async decrypt fails, tls_decrypt_done() records the error in
ctx->async_wait.err and calls tls_err_abort(), which stores it in
sk_err. tls_sw_recvmsg() and tls_sw_read_sock() each read
async_wait.err once they hold the reader lock and fail the call: a
record that did not authenticate breaks the connection.

tls_sw_splice_read() has no such check, and sk_err does not stand in
for one. tls_rx_rec_wait() tests sk_err only inside the loop it
skips whenever a record is already parsed, and the first reader to
reach sock_error() clears it, while async_wait.err persists. A
splice therefore keeps delivering records on a connection that
recvmsg() and read_sock() refuse to read.

Read async_wait.err in tls_sw_splice_read() as the other two readers
do.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version f314bfee81b1bf8e01168177b2f65f24eb8da63a
Version < a808aadff634c7a408b2ab84d5919e9a741fdb5b
Status affected
Version f314bfee81b1bf8e01168177b2f65f24eb8da63a
Version < 06c2a53604fa1dc4820063828d7dadb3675b7af8
Status affected
Version f314bfee81b1bf8e01168177b2f65f24eb8da63a
Version < 18ae1e95f20867106a28820c208a9cec99dda861
Status affected
Version f314bfee81b1bf8e01168177b2f65f24eb8da63a
Version < 82d9269f01ebfd835b6256aa17016a974cbbc647
Status affected
Version f314bfee81b1bf8e01168177b2f65f24eb8da63a
Version < 4b177911eb9f799e9841c2f87c75b08cb112757a
Status affected
Version f314bfee81b1bf8e01168177b2f65f24eb8da63a
Version < 976df67f463db1fddaf2a32fb04f57ad2891a23d
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.19
Status affected
Version 0
Version < 5.19
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.153
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.056
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/a808aadff634c7a408b2ab84d5919e9a741fdb5b
https://git.kernel.org/stable/c/06c2a53604fa1dc4820063828d7dadb3675b7af8
https://git.kernel.org/stable/c/18ae1e95f20867106a28820c208a9cec99dda861
https://git.kernel.org/stable/c/82d9269f01ebfd835b6256aa17016a974cbbc647
https://git.kernel.org/stable/c/4b177911eb9f799e9841c2f87c75b08cb112757a
https://git.kernel.org/stable/c/976df67f463db1fddaf2a32fb04f57ad2891a23d